Johan Cwiklinski
24 exploits
Active since Mar 2019
GLPI < 9.4.6 - Authenticated Remote Code Execution via Backup Functionality
CVSS 7.4
Galette < 0.9.5 - Stored Cross-Site Scripting in Self Subscription Page
CVSS 6.8
GLPI < 9.4.6 - Use of Hard-coded Credentials via Default GLPIKEY
CVSS 7.2
Galette < 0.9.5 - Stored Cross-Site Scripting in Self Subscription Page
CVSS 6.8
GLPI 9.3.0-9.5.7 - Unauthenticated SQL Injection via Login Page
CVSS 9.8
Teclib GLPI < 9.3.3 - SQL Injection via Cycle Parameter
CVSS 9.8
GLPI < 9.4.1 - Weak Password Recovery Mechanism for Forgotten Password
CVSS 5.9
GLPI < 9.5.0 - Use of a Broken or Risky Cryptographic Algorithm
CVSS 7.8
GLPI 0.68.1-9.4.6 - Reflected Cross-Site Scripting via Dropdown Endpoints
CVSS 6.0
glpi < 9.5.1 - SQL Injection via Clone Feature
CVSS 7.1
GLPI < 9.5.2 - SQL Injection via Backtick Input
CVSS 8.7
GLPI 9.5.0-9.5.4 - Cross-Site Scripting via ajax/kanban.php
CVSS 6.8
Galette < 0.9.5 - Stored Cross-Site Scripting in Self Subscription Page
CVSS 6.8
Galette < 0.9.6 - Cross-Site Request Forgery
CVSS 8.2
Galette < 0.9.6 - Authenticated Stored Cross-Site Scripting via Preferences Footer
CVSS 8.1
Galette < 0.9.6 - Authenticated SQL Injection
CVSS 8.8
GLPI < 10.0.0 - Unauthenticated LDAP Password Exposure via JavaScript Config
CVSS 7.5
GLPI 10.0.0-10.0.10 - SQL Injection via Inventory Endpoint
CVSS 8.6
Galette 1.0.0-1.0.1 - Incorrect Authorization
CVSS 7.5
GLPI 0.65-10.0.12 - Authenticated SQL Injection via Search Engine
CVSS 7.7
GLPI 9.5.0-10.0.12 - Authenticated Server-Side Request Forgery via Arbitrary Object Instantiation
CVSS 6.4
GLPI 9.3.0-10.0.14 - Authenticated SQL Injection via Map Search
CVSS 7.7
GLPI Inventory Plugin <1.5.0 - Privilege Escalation
CVSS 8.2
GLPI 9.5.0-10.0.18 - Stored Cross-Site Scripting in Project Kanban
CVSS 4.5